Rasmus Wriedt Larsen
|
68d00a829e
|
Merge pull request #14430 from RasmusWL/api-graph-import-star
Python: Better allow `import *` to work with API graphs
|
2023-10-11 10:03:46 +02:00 |
|
Erik Krogh Kristensen
|
6377e92067
|
Update javascript/ql/lib/semmle/javascript/dataflow/DataFlow.qll
Co-authored-by: Asger F <asgerf@github.com>
|
2023-10-11 09:52:48 +02:00 |
|
Erik Krogh Kristensen
|
e99b1598d1
|
Merge pull request #14433 from erik-krogh/delete-expected
JS: delete an .expected file outside the test directories
|
2023-10-11 09:44:04 +02:00 |
|
Tamás Vajk
|
c587dbb72a
|
Merge pull request #14428 from tamasvajk/feature/deterministic-conflict-resolution
C#: Make conflicting assembly selection deterministic in standalone
|
2023-10-11 08:40:50 +02:00 |
|
amammad
|
4499048d8e
|
better query quality thanks to owen
|
2023-10-10 23:41:45 +02:00 |
|
amammad
|
877605d31b
|
change c to C for fixing the qhelp error :)
|
2023-10-10 23:35:05 +02:00 |
|
amammad
|
b6968d9260
|
fix beego tests
|
2023-10-10 23:30:26 +02:00 |
|
amammad
|
8d6f985aea
|
fix afero additional step and tests
|
2023-10-10 23:24:04 +02:00 |
|
amammad
|
db9f74bc78
|
fix tests
|
2023-10-10 23:15:07 +02:00 |
|
amammad
|
82483a206e
|
fix tests
|
2023-10-10 23:14:11 +02:00 |
|
amammad
|
38b0ed8176
|
fix issues according to codereview
|
2023-10-10 23:12:30 +02:00 |
|
erik-krogh
|
ccd06c78b9
|
delete an .expected file outside the test directories
|
2023-10-10 21:35:19 +02:00 |
|
Robert Marsh
|
484d020c39
|
Merge branch 'main' into rdmarsh2/swift/autoclosure-cfg
|
2023-10-10 18:47:13 +00:00 |
|
Eric Bickle
|
7a4382fb69
|
Merge branch 'main' into fix/thread-resource-arithmetic
|
2023-10-10 09:38:16 -07:00 |
|
Eric Bickle
|
80c8259e34
|
Remove unnecessary AdditionalValueStep check
|
2023-10-10 09:35:45 -07:00 |
|
Mathias Vorreiter Pedersen
|
f1cefc8900
|
Merge branch 'main' into select-the-right-node-for-flow-sources
|
2023-10-10 17:35:37 +01:00 |
|
Mathias Vorreiter Pedersen
|
496f190d70
|
C++: Accept test changes.
|
2023-10-10 16:45:31 +01:00 |
|
Mathias Vorreiter Pedersen
|
512c10ec59
|
C++: Use the fully converted expression when converting models to dataflow nodes.
|
2023-10-10 16:45:25 +01:00 |
|
Rasmus Wriedt Larsen
|
ee75b104eb
|
Python: Add change-note
|
2023-10-10 17:45:11 +02:00 |
|
Rasmus Wriedt Larsen
|
72d0dcdaba
|
Python: Workaround for module level items from import * not being LocalSourceNodes
|
2023-10-10 17:45:11 +02:00 |
|
Rasmus Wriedt Larsen
|
6521e5165c
|
Python: Extend import * with plain use
(no calls or anything)
|
2023-10-10 17:45:11 +02:00 |
|
yoff
|
f1266a3e81
|
Merge pull request #14417 from github/tausbn/python-add-flow-for-assignment-expressions
|
2023-10-10 17:09:20 +02:00 |
|
Tamas Vajk
|
4c6073ebce
|
C#: Remove keyset from metadata_handle relation
|
2023-10-10 16:49:48 +02:00 |
|
Tamas Vajk
|
2378e31c5e
|
C#: Make conflicting assembly selection deterministic
|
2023-10-10 16:32:02 +02:00 |
|
Michael B. Gale
|
be16cb4190
|
Merge pull request #14415 from github/mbg/go/dependabot-config
|
2023-10-10 14:36:34 +01:00 |
|
Michael B. Gale
|
ce905bba41
|
Apply suggestions from code review
Co-authored-by: Owen Mansel-Chan <62447351+owen-mc@users.noreply.github.com>
|
2023-10-10 14:21:20 +01:00 |
|
Tamás Vajk
|
bc1c22cda2
|
Merge pull request #14425 from tamasvajk/standalone/nuget-download-lazy
C#: Only download nuget.exe if there are packages.config files
|
2023-10-10 14:28:43 +02:00 |
|
Rasmus Wriedt Larsen
|
2d947a4f53
|
Merge pull request #13781 from maikypedia/maikypedia/python-unsafe-deserialization
Python: Add unsafe deserialization sinks (CWE-502)
|
2023-10-10 13:30:38 +02:00 |
|
Owen Mansel-Chan
|
542d5a2451
|
Merge pull request #14414 from owen-mc/go/fix-incorrect-integer-conversion-performance-regression
Go: Change MaxValueState API to get architecture bit size
|
2023-10-10 11:27:18 +01:00 |
|
Jeroen Ketema
|
3b777c2764
|
C++: Rewrite cpp/cgi-xss to not use default taint tracking
Also add a test that demonstrates that we need to look at inidrect expressions
and not direct ones.
|
2023-10-10 11:56:39 +02:00 |
|
Tamas Vajk
|
1872a937d5
|
C#: Only download nuget.exe if there are packages.config files
|
2023-10-10 11:39:39 +02:00 |
|
Owen Mansel-Chan
|
fd9c1d30f9
|
Remove argument that is always one value
|
2023-10-10 10:35:04 +01:00 |
|
Owen Mansel-Chan
|
cf0411e7e2
|
Change MaxValueState API to get architecture bit size
This fixes a performance regression, though it is not clear why.
|
2023-10-10 10:35:02 +01:00 |
|
Taus
|
8e1bb4b364
|
Python: Accept moved consistency test results
Co-authored-by: Rasmus Lerchedahl Petersen <yoff@github.com>
|
2023-10-10 09:22:36 +00:00 |
|
Geoffrey White
|
0d562d4874
|
Swift: Autoformat.
|
2023-10-10 10:01:37 +01:00 |
|
Geoffrey White
|
48ee4add08
|
Merge branch 'main' into sqlpathinject3
|
2023-10-10 08:54:44 +01:00 |
|
Geoffrey White
|
0374414798
|
Swift: Fix TupleElement syntax.
|
2023-10-10 08:31:50 +01:00 |
|
Michael Nebel
|
5c44f8bbad
|
Merge pull request #14370 from michaelnebel/java/enablethreatmodels
Java: Enable threat models for most Java queries.
|
2023-10-10 09:25:47 +02:00 |
|
Tamas Vajk
|
538df1bb6d
|
C#: Add autobuilder test with global.json
|
2023-10-10 09:11:40 +02:00 |
|
Erik Krogh Kristensen
|
5cb3543899
|
Merge pull request #14420 from github/dependabot/cargo/ql/regex-1.10.0
Bump regex from 1.9.6 to 1.10.0 in /ql
|
2023-10-10 08:43:46 +02:00 |
|
dependabot[bot]
|
0e09420e7b
|
Bump regex from 1.9.6 to 1.10.0 in /ql
Bumps [regex](https://github.com/rust-lang/regex) from 1.9.6 to 1.10.0.
- [Release notes](https://github.com/rust-lang/regex/releases)
- [Changelog](https://github.com/rust-lang/regex/blob/master/CHANGELOG.md)
- [Commits](https://github.com/rust-lang/regex/compare/1.9.6...1.10.0)
---
updated-dependencies:
- dependency-name: regex
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2023-10-10 03:56:00 +00:00 |
|
Erik Krogh Kristensen
|
4489e2bf28
|
Merge pull request #14403 from erik-krogh/dDEps
All: delete outdated deprecations
|
2023-10-09 21:04:55 +02:00 |
|
amammad
|
2579791f51
|
fix examples
|
2023-10-09 19:00:55 +02:00 |
|
Jeroen Ketema
|
fe60269fdd
|
Merge pull request #14416 from jketema/revert-cgi-xss-rewrite
Revert "C++: Rewrite `cpp/cgi-xss` to not use default taint tracking"
|
2023-10-09 18:52:54 +02:00 |
|
Jeroen Ketema
|
6ff8e06ace
|
Revert "C++: Rewrite cpp/cgi-xss to not use default taint tracking"
This reverts commit b6132d2a0f.
|
2023-10-09 16:30:21 +02:00 |
|
Robert Marsh
|
dab9a859f3
|
Merge branch 'main' into rdmarsh2/swift/autoclosure-cfg
|
2023-10-09 14:21:28 +00:00 |
|
Taus
|
e8ac258994
|
Python: Add missing flow for AssignmentExpr nodes
Also extend the tests surrounding this construct to be a bit more comprehensive.
Co-authored-by: Rasmus Lerchedahl Petersen <yoff@github.com>
|
2023-10-09 14:16:03 +00:00 |
|
Michael B. Gale
|
f186b93c93
|
Add dependabot configuration for Go dependencies
|
2023-10-09 15:14:17 +01:00 |
|
Robert Marsh
|
8af727734e
|
Merge pull request #13909 from rdmarsh2/rdmarsh2/swift/for-in
Swift: dataflow for `for-in` loops
|
2023-10-09 10:00:27 -04:00 |
|
Michael B. Gale
|
ebd640da04
|
Merge pull request #14391 from github/mbg/go/update-newer-go-version-needed
Go: Fix version detection and test for `newer-go-version-needed`
|
2023-10-09 14:47:37 +01:00 |
|